All of lore.kernel.org
 help / color / mirror / Atom feed
From: sanan.hasanou@gmail.com
To: tytso@mit.edu, adilger.kernel@dilger.ca,
	linux-ext4@vger.kernel.org, linux-kernel@vger.kernel.org
Cc: syzkaller@googlegroups.com, contact@pgazz.com
Subject: WARNING: at ext4_check_map_extents_env, CPU: syz.NUM.NUM/NUM
Date: Thu, 18 Jun 2026 15:24:40 -0700 (PDT)	[thread overview]
Message-ID: <6a347028.d133b7cb.2a669a.5815@mx.google.com> (raw)

Good day, dear maintainers,

We found a bug using a modified version of syzkaller.

Kernel Branch: 7.0-rc1
Kernel Config: <https://drive.google.com/open?id=173DLEAEPKPhhR1TcqofdnkLpdoK7PMFl>
Reproducer: <https://drive.google.com/open?id=1_mGsSS7wCRfk8qXdMEw08C6S49PejwXr>
Thank you!

Best regards,
Sanan Hasanov

EXT4-fs (loop0): stripe (65535) is not aligned with cluster size (16), stripe is disabled
[EXT4 FS bs=1024, gc=1, bpg=131072, ipg=32, mo=a840e11d, mo2=0002]
------------[ cut here ]------------
WARNING: at ext4_check_map_extents_env+0x471/0x510 fs/ext4/inode.c:436, CPU#0: syz.0.1217/21399
Modules linked in:
CPU: 0 UID: 0 PID: 21399 Comm: syz.0.1217 Not tainted 7.0.0-rc1 #1 PREEMPT(full) 
Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
RIP: 0010:ext4_check_map_extents_env+0x471/0x510 fs/ext4/inode.c:436
Code: ff e9 89 fc ff ff 44 89 e1 80 e1 07 80 c1 03 38 c1 0f 8c 05 fd ff ff 4c 89 e7 e8 da d6 ae ff e9 f8 fc ff ff e8 60 a7 42 ff 90 <0f> 0b 90 e9 8a fc ff ff 44 89 e1 80 e1 07 80 c1 03 38 c1 0f 8c 25
RSP: 0018:ffffc90002ce76c8 EFLAGS: 00010287
RAX: ffffffff827faa70 RBX: 0000000000000000 RCX: 0000000000080000
RDX: ffffc900019f5000 RSI: 00000000000030b1 RDI: 00000000000030b2
RBP: 0000000000000000 R08: ffff888017201637 R09: 1ffff11002e402c6
R10: dffffc0000000000 R11: ffffed1002e402c7 R12: 0000000000000000
R13: dffffc0000000000 R14: 0000000000000000 R15: 0000000000000000
FS:  00007fbe746086c0(0000) GS:ffff8880d98df000(0000) knlGS:0000000000000000
CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007fe495821940 CR3: 00000000683d9000 CR4: 00000000000006f0
Call Trace:
 <TASK>
 ext4_map_blocks+0x1e9/0x1540 fs/ext4/inode.c:721
 ext4_protect_reserved_inode fs/ext4/block_validity.c:168 [inline]
 ext4_setup_system_zone+0x872/0xa90 fs/ext4/block_validity.c:251
 __ext4_fill_super fs/ext4/super.c:5594 [inline]
 ext4_fill_super+0x534c/0x6390 fs/ext4/super.c:5791
 get_tree_bdev_flags+0x3fe/0x4c0 fs/super.c:1694
 vfs_get_tree+0x8e/0x290 fs/super.c:1754
 fc_mount fs/namespace.c:1193 [inline]
 do_new_mount_fc fs/namespace.c:3760 [inline]
 do_new_mount+0x31f/0xd40 fs/namespace.c:3836
 do_mount fs/namespace.c:4159 [inline]
 __do_sys_mount fs/namespace.c:4348 [inline]
 __se_sys_mount+0x3a1/0x4b0 fs/namespace.c:4325
 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
 do_syscall_64+0x19a/0x7b0 arch/x86/entry/syscall_64.c:94
 entry_SYSCALL_64_after_hwframe+0x4b/0x53
RIP: 0033:0x7fbe737a559e
Code: 0f 1f 40 00 48 c7 c2 b0 ff ff ff f7 d8 64 89 02 b8 ff ff ff ff c3 66 0f 1f 44 00 00 f3 0f 1e fa 49 89 ca b8 a5 00 00 00 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b0 ff ff ff f7 d8 64 89 01 48
RSP: 002b:00007fbe74607e28 EFLAGS: 00000246 ORIG_RAX: 00000000000000a5
RAX: ffffffffffffffda RBX: 00007fbe74607ec0 RCX: 00007fbe737a559e
RDX: 0000200000000080 RSI: 0000200000000040 RDI: 00007fbe74607e80
RBP: 0000200000000080 R08: 00007fbe74607ec0 R09: 0000000000000011
R10: 0000000000000011 R11: 0000000000000246 R12: 0000200000000040
R13: 00007fbe74607e80 R14: 000000000000060c R15: 0000200000000180
 </TASK>

<<<<<<<<<<<<<<< tail report >>>>>>>>>>>>>>>

                 reply	other threads:[~2026-06-18 22:24 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=6a347028.d133b7cb.2a669a.5815@mx.google.com \
    --to=sanan.hasanou@gmail.com \
    --cc=adilger.kernel@dilger.ca \
    --cc=contact@pgazz.com \
    --cc=linux-ext4@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=syzkaller@googlegroups.com \
    --cc=tytso@mit.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.